Policies

[System].Core.Global Policies.Agent Settings

  • Agent (Core)
    • Policy View: zz[SYS] Policy - Agent_Has Checked In
    • Description: Agent (Core) - Applies common agent settings for all managed machines. Agent Icon is enabled but only Refresh option is enabled. Check-In control is set to 30 seconds with "Warn if multiple agents use same account" and "Warn if agent on same LAN as KServer connects through gateway" both enabled. Agent Log History for all logs is set to 31 days.
  • Windows Agent
    • Policy View: zz[SYS] Policy - OS_All Windows
    • Description: Windows Agent - Applies agent settings specific to Windows. Sets agent working directory to c:\kworking.
  • Linux Agent
    • Policy View: zz[SYS] Policy - OS_All Linux
    • Description: Linux Agent - Applies agent settings specific to Linux. Sets agent working directory to /tmp/kworking.
  • MacOS Agent
    • Policy View:zz[SYS] Policy - OS_All Mac OS X
    • Description:MacOS Agent - Applies agent settings specific to MacOS Workstations. Sets agent working directory to /Library/Kaseya/kworking.

[System].Core.Global Policies.Remote Support

  • Server RC Notification Policy (Silent w Admin Note)
    • Policy View: zz[SYS] Policy - OS_All Servers
    • Description: Server RC Notification Policy (Silent w Admin Note) - Applies Remote Control notification settings for all servers. Sets user notification type to Silently take control, and enables the Require admin note to start remote control option.
  • Workstation RC Notification Policy (Alert/Term w Admin Note)
    • Policy View:zz[SYS] Policy - OS_All Workstations
    • Description:Workstation RC Notification Policy (Alert/Term w Admin Note) - Applies Remote Control notification settings for all workstations. Sets user notification type to If user logged in display alert, Notify user when session terminates, and enables the Require admin note to start remote control option.

[System].Core.Org Specific Policies.Agent Settings

  • Agent (Hidden)
    • Policy View: zz[SYS] Policy - Agent_Has Checked In
    • Description: Agent (Hidden) - Applies common agent settings for all managed machines. Agent Icon is disabled/hidden. Check-In control is set to 30 seconds with "Warn if multiple agents use same account" and "Warn if agent on same LAN as KServer connects through gateway" both enabled. Agent Log History for all logs is set to 31 days.
  • Agent (Server)
    • Policy View:zz[SYS] Policy - OS_All Servers
    • Description:Agent (Server) - Applies common agent settings for all managed servers. Agent Icon is enabled with Disable Remote Control, Refresh and Exit. Check-In control is set to 30 seconds with "Warn if multiple agents use same account" and "Warn if agent on same LAN as KServer connects through gateway" both enabled. Agent Log History for all logs is set to 93 days.
  • Agent (Workstation)
    • Policy View:zz[SYS] Policy - OS_All Workstations
    • Description: Agent (Workstation) - Applies common agent settings for all managed workstations. Agent Icon is enabled with Contact Help Desk, Disable Remote Control and Refresh. Check-In control is set to 30 seconds with "Warn if multiple agents use same account" and "Warn if agent on same LAN as KServer connects through gateway" both enabled. Agent Log History for all logs is set to 31 days.

[System].Core.Org Specific Policies.Remote Support

  • Server RC Notification Policy (Silent w/o Admin Note)
    • Policy View: zz[SYS] Policy - OS_All Servers
    • Description: Server RC Notification Policy (Silent w/o Admin Note) - Applies Remote Control notification settings for all servers. Sets user notification type to Silently take control and does not require an Admin Note to start remote control.
  • Workstation RC Notification Policy (Alert/Term w/o Admin Note)
    • Policy View: zz[SYS] Policy - OS_All Workstations
    • Description: Workstation RC Notification Policy (Alert/Term w/o Admin Note) - Applies Remote Control notification settings for all workstations. Sets user notification type to If user logged in display alert, Notify user when session terminates, and does not require an Admin Note to start remote control.
  • Workstation RC Notification Policy (Silent w Admin Note)
    • Policy View:zz[SYS] Policy - OS_All Workstations
    • Description: Workstation RC Notification Policy (Silent w Admin Note) - Applies Remote Control notification settings for all workstations. Sets user notification type to Silently take control but requires an Admin Note to start remote control.

[System].Core.Org Specific Policies.Audit / Inventory.Schedules.Baseline.Baseline Audit Schedule (Annually Daytime)

  • Baseline Audit Schedule (Annually Jan 1-7 6am-6pm/Power Mgmt)
    • Policy View:zz[SYS] Policy - Agent_Has Checked In
    • Description: Baseline Audit Schedule (Annually Jan 1-7 6am-6pm/Power Mgmt) - Applies a scheduled Annual Baseline Audit for all machines that have been deployed and have checked in beginning on January 1st through the 7th between 6am-6pm. The policy uses the power management feature at the scheduled audit time attempting to wake a powered off machine prior to the audit. The policy is generally used in situations where annual audits may be required for planning or compliancy purposes and so that for relevant Baseline/Latest Audit comparisons can be performed for operational tasks. The policy can be selectively applied to various machines, machine groups, and/or entire organizations of machines.

[System].Core.Org Specific Policies.Audit / Inventory.Schedules.Latest/SysInfo.Daily.Latest/SysInfo Audit Schedule (Daily Daytime)

  • Latest/SysInfo Audit Schedule (Daily M-F 6am-6pm/Power Mgmt)
    • Policy View: zz[SYS] Policy - Agent_Has Checked In
    • Description: Latest/SysInfo Audit Schedule (Daily M-F 6am-6pm/Power Mgmt) - Applies scheduled Latest and System Info Audits for all machines that have checked in to run daily (M-F) between 6am-6pm. The policy uses the power management feature at the scheduled audit time attempting to wake a powered off machine prior to the audit. The policy is generally used in situations where customers need to run audits during business hours on weekdays because machines are generally turned off at night and on weekends. The policy can be selectively applied to various machines, machine groups, and/or entire organizations of machines.

[System].Core.Org Specific Policies.Audit / Inventory.Schedules.Latest/SysInfo.Daily.Latest/SysInfo Audit Schedule (Daily Nighttime)

  • Latest/SysInfo Audit Schedule (Daily M-F 6pm-6am/Power Mgmt)
    • Policy View: zz[SYS] Policy - Agent_Has Checked In
    • Description:Latest/SysInfo Audit Schedule (Daily M-F 6pm-6am/Power Mgmt) - Applies scheduled Latest and System Info Audits for all machines that have checked in to run daily (M-F) between 6pm-6am. The policy uses the power management feature at the scheduled audit time attempting to wake a powered off machine prior to the audit. The policy is generally used in situations where customers prefer to run audits in the evening when systems are less utilized than during business hours and when machines are either left on at night or have been configured for Wake-On-LAN or vPro Power Management so that can be woken if powered off at night. The policy can be selectively applied to various machines, machine groups, and/or entire organizations of machines.

[System].Core.Org Specific Policies.Audit / Inventory.Schedules.Latest/SysInfo.Weekly.Latest/SysInfo Audit Schedule (Weekly Daytime)

  • Latest/SysInfo Audit Schedule (Weekly M-F 6am-6pm/Power Mgmt)
    • Policy View:zz[SYS] Policy - Agent_Has Checked In
    • Description:Latest/SysInfo Audit Schedule (Weekly M-F 6am-6pm/Power Mgmt) - Applies scheduled Latest and System Info Audits for all machines that have checked in to run weekly (M-F) between 6am-6pm. The policy uses the power management feature at the scheduled audit time attempting to wake a powered off machine prior to the audit. The policy is generally used in situations where customers need to run audits during business hours on weekdays because machines are generally turned off at night and on weekends. The policy can be selectively applied to various machines, machine groups, and/or entire organizations of machines.

[System].Core.Org Specific Policies.Audit / Inventory.Schedules.Latest/SysInfo.Weekly.Latest/SysInfo Audit Schedule (Weekly Nighttime)

  • Latest/SysInfo Audit Schedule (Weekly M-F 6pm-6am/Power Mgmt)
    • Policy View:zz[SYS] Policy - Agent_Has Checked In
    • Description: Latest/SysInfo Audit Schedule (Weekly M-F 6pm-6am/Power Mgmt) - Applies scheduled Latest and System Info Audits for all machines that have checked in to run weekly (M-F) between 6pm-6am. The policy uses the power management feature at the scheduled audit time attempting to wake a powered off machine prior to the audit. The policy is generally used in situations where customers prefer to run audits in the evening when systems are less utilized than during business hours and when machines are either left on at night or have been configured for Wake-On-LAN or vPro Power Management so that can be woken if powered off at night. The policy can be selectively applied to various machines, machine groups, and/or entire organizations of machines.

[System].Core.Org Specific Policies.Maintenance.Windows Workstation Recurring Maintenance

  • Windows Workstation Maintenance (Weekly M-F 6pm-6am)
    • Policy View: zz[SYS] Policy - OS_All Windows Workstations
    • Description:Windows Workstation Maintenance (Weekly M-F 6pm-6am) - Applies a scheduled Windows Workstation maintenance procedure to run on all Windows Workstation machines weekly (M-F) between 6pm-6am. If the machine is not turned on when the maintenance is scheduled, then the machine will skip that maintenance cycle and will attempt to run the maintenance again a week later.

[System].Core.Org Specific Policies.Maintenance.MacOS Workstation Recurring Maintenance

  • MacOS Maintenance Schedule (Weekly M-F 6pm-6am)
    • Policy View: zz[SYS] Policy - OS_All Mac OS X Workstations
    • Description:MacOS Maintenance Schedule (Weekly M-F 6pm-6am) - Applies a scheduled MacOS maintenance procedure to run on all MacOS machines weekly (M-F) between 6pm-6am. If the machine is not turned on when the maintenance is scheduled, then the machine will skip that maintenance cycle and will attempt to run the maintenance again a week later.

[System].Core.Org Specific Policies.Maintenance.Linux Recurring Maintenance

  • Linux Maintenance Schedule (Weekly M-F 6pm-6am)
    • Policy View: zz[SYS] Policy - OS_All Linux
    • Description:Linux Maintenance Schedule (Weekly M-F 6pm-6am) - Applies a scheduled Linux maintenance procedure to run on all Linux machines weekly (M-F) between 6pm-6am. If the machine is not turned on when the maintenance is scheduled, then the machine will skip that maintenance cycle and will attempt to run the maintenance again a week later.

[System].Core.Org Specific Policies.Maintenance.Windows Server Recurring Maintenance

  • Windows Server Maintenance (Weekly Sun 12am-4am)
    • Policy View:zz[SYS] Policy - OS_All Windows Servers
    • Description:Windows Server Maintenance (Weekly Sun 12am-4am) - Applies a scheduled Windows Server maintenance procedure to run on all Windows Server machines weekly on Sunday between 12am-4am. If the machine is not turned on when the maintenance is scheduled, then the machine will skip that maintenance cycle and will attempt to run the maintenance again a week later.

[System].Core.Org Specific Policies.Monitoring.Server

  • Server Roles Enhanced Audit
    • Policy View: zz[SYS] Policy - OS_All Windows Servers
    • Description: Server Roles Enhanced Audit - Applies a scheduled Enhanced Audit to run weekly on Sun between 12am-4am in order to identify server functional roles so that monitoring policies can be applied properly based on those roles.
  • Common Windows Server Monitoring
    • Policy View: zz[SYS] Policy - OS_All Windows Servers
    • Description: Common Windows Server Monitoring - Applies a common set of monitoring to all Windows Servers. This includes hardware related Events Log, Windows Service, and common Windows Performance monitoring.
  • Windows Server (Core)
    • Policy View: zz[SYS] Policy - OS_All Windows Servers
    • Description: Windows Server (Core) - Applies an array of core Windows Server monitoring to Windows Servers including monitoring for standard services, system performance, health reporting, event logs, and more.
  • Windows Server 2003
    • Policy View:zz[SYS] Policy - OS_Win 2003 Server
    • Description:Windows Server 2003 - Applies standard service monitoring for Windows 2003 Servers.
  • Windows Server 2008/2008 R2
    • Policy View:zz[SYS] Policy - OS_Win 2008 Server
    • Description:Windows Server 2008/2008 R2 - Applies standard service monitoring for Windows 2008/2008 R2 Servers.
  • Windows Server 2012
    • Policy View: zz[SYS] Policy - OS_Win 2012 Server
    • Description: Windows Server 2012 - Applies standard service monitoring for Windows 2012 Servers.

[System].Core.Org Specific Policies.Monitoring.Server.Hardware

  • Dell PowerEdge
    • Policy View:zz[SYS] Policy - HW_Dell PowerEdge
    • Description: Dell PowerEdge - Applies Dell PowerEdge server hardware specific monitoring and alerting. This monitoring may require specific Dell PowerEdge server management tools to be installed on the server machine.
  • HP ProLiant
    • Policy View:zz[SYS] Policy - HW_HP ProLiant
    • Description:HP ProLiant - Applies HP ProLiant server hardware specific monitoring and alerting. This monitoring may require specific HP ProLiant server management tools to be installed on the server machine.
  • IBM Series x
    • Policy View:zz[SYS] Policy - HW_IBM Series X
    • Description:IBM Series x - Applies IBM Series X server hardware specific monitoring and alerting. This monitoring may require specific IBM Series X server management tools to be installed on the server machine.

[System].Core.Org Specific Policies.Monitoring.Server.Roles

  • Backup Exec Server
    • Policy View:zz[SYS] Policy - Role_Backup Exec Server
    • Description:Backup Exec Server - Applies monitoring to Backup Exec Servers.
  • Blackberry Enterprise Server
    • Policy View:zz[SYS] Policy - Role_Blackberry Server
    • Description:Blackberry Enterprise Server - Applies monitoring to Blackberry Enterprise Servers.
  • BrightStor ARCServe Server
    • Policy View:zz[SYS] Policy - Role_Brightstor ARCserve Server
    • Description: BrightStor ARCServe Server - Applies monitoring to BrightStor Servers.
  • Citrix Server
    • Policy View:zz[SYS] Policy - Role_Citrix Server
    • Description: Citrix Server - Applies monitoring to Citrix Servers.
  • DHCP Server
    • Policy View:zz[SYS] Policy - Role_DHCP Server
    • Description: DHCP Server - Applies monitoring to DHCP Servers.
  • DNS Server
    • Policy View:zz[SYS] Policy - Role_DNS Server
    • Description:DNS Server - Applies monitoring to DNS Servers.
  • Domain Controller
    • Policy View:zz[SYS] Policy - Role_Domain Controller
    • Description: Domain Controller - Applies monitoring to Domain Controllers.
  • Exchange 2003 Server
    • Policy View:zz[SYS] Policy - Role_Exchange 2003 Server
    • Description:Exchange 2003 Server - Applies monitoring to Exchange 2003 Servers.
  • Exchange 2007 Server
    • Policy View:zz[SYS] Policy - Role_Exchange 2007 Server
    • Description:Exchange 2007 Server - Applies monitoring to Exchange 2007 Servers.
  • Exchange 2010 Server
    • Policy View:zz[SYS] Policy - Role_Exchange 2010 Server
    • Description: Exchange 2010 Server - Applies monitoring to Exchange 2010 Servers.
  • Exchange Server
    • Policy View:zz[SYS] Policy - Role_Exchange Server
    • Description:Exchange Server - Applies monitoring to Exchange Servers
  • File Server
    • Policy View:zz[SYS] Policy - Role_File Server
    • Description:File Server - Applies monitoring to File Servers
  • FTP Server
    • Policy View:zz[SYS] Policy - Role_FTP Server
    • Description: FTP Server - Applies monitoring to FTP Servers.
  • IIS Server
    • Policy View:zz[SYS] Policy - Role_IIS Server
    • Description: IIS Server - Applies monitoring to IIS Servers
  • IMAP4 Server
    • Policy View: zz[SYS] Policy - Role_IMAP4 Server
    • Description: IMAP4 Server - Applies monitoring to IMAP4 Servers.
  • POP3 Server
    • Policy View: zz[SYS] Policy - Role_POP3 Server
    • Description: POP3 Server - Applies monitoring to POP3 Servers.
  • Print Server
    • Policy View:zz[SYS] Policy - Role_Print Server
    • Description:Print Server - Applies monitoring to Print Servers
  • SharePoint Server
    • Policy View: zz[SYS] Policy - Role_SharePoint Server
    • Description: SharePoint Server - Applies monitoring to SharePoint Servers
  • SMTP Server
    • Policy View:zz[SYS] Policy - Role_SMTP Server
    • Description: SMTP Server - Applies monitoring to SMTP Servers.
  • SQL Server
    • Policy View:zz[SYS] Policy - Role_SQL Server
    • Description: SQL Server - Applies monitoring to SQL Servers.
  • SQL Server 2005
    • Policy View:zz[SYS] Policy - Role_SQL Server 2005
    • Description:SQL Server 2005 - Applies monitoring to SQL 2005 Servers.
  • SQL Server 2008
    • Policy View:zz[SYS] Policy - Role_SQL Server 2008
    • Description:SQL Server 2008 - Applies monitoring to SQL 2008 Servers.
  • Terminal Server
    • Policy View:zz[SYS] Policy - Role_Terminal Server
    • Description: Terminal Server - Applies monitoring to Terminal Servers.
  • WINS Server
    • Policy View:zz[SYS] Policy - Role_WINS Server
    • Description: WINS Server - Applies monitoring to WINS Servers.

[System].Core.Org Specific Policies.Monitoring.Workstation

  • Common Windows Workstation Monitoring
    • Policy View:zz[SYS] Policy - OS_All Windows Workstations
    • Description:Common Windows Workstation Monitoring - Applies a common set of monitoring to all Windows Workstations. This includes hardware related Events Log, Windows Service, and common Windows Performance monitoring.
  • Windows Workstation (Core)
    • Policy View:zz[SYS] Policy - OS_All Windows Workstations
    • Description:Windows Workstation (Core) - Applies an array of core Windows Workstation monitoring to Windows Workstations including monitoring for standard services, system performance, health reporting, and more.
  • Windows Vista
    • Policy View:zz[SYS] Policy - OS_Win Vista
    • Description:Windows Vista - Applies standard service monitoring for Windows Vista machines.
  • Windows 7
    • Policy View:zz[SYS] Policy - OS_Win 7
    • Description:Windows 7 - Applies standard service monitoring for Windows 7 machines.
  • Windows XP
    • Policy View:zz[SYS] Policy - OS_Win XP
    • Description:Windows XP - Applies standard service monitoring for Windows XP machines.
  • Windows 8
    • Policy View: zz[SYS] Policy - OS_Win 8
    • Description: Windows 8 - Applies standard service monitoring for Windows 8 machines.

[System].Core.Org Specific Policies.Monitoring.Security.Anti-Virus

  • AVG Tech
    • Policy View:zz[SYS] Policy - AV_AVG Technologies
    • Description:AVG - Applies monitoring for AVG Technologies AntiVirus.
  • Kaspersky ES
    • Policy View:zz[SYS] Policy - AV_Kaspersky ES
    • Description:Kaspersky ES - Applies monitoring for Kaspersky Endpoint Security.
  • McAfee
    • Policy View:zz[SYS] Policy - AV_McAfee
    • Description:McAfee - Applies monitoring for McAfee AntiVirus.
  • Microsoft SE-FEP
    • Policy View: zz[SYS] Policy - AV_Microsoft SE-FEP
    • Description: Microsoft SE-FEP - Applies monitoring for Microsoft Security Essentials and Forefront Endpoint Protection.
  • Sophos
    • Policy View:zz[SYS] Policy - AV_Sophos
    • Description: Sophos - Applies monitoring for Sophos AntiVirus.
  • Symantec AV
    • Policy View:zz[SYS] Policy - AV_Symantec AV
    • Description: Symantec zz[SYS] AV - Applies monitoring for Symantec AntiVirus.
  • Symantec EP
    • Policy View: zz[SYS] Policy - AV_Symantec EP
    • Description: Symantec EP - Applies monitoring for Symantec Endpoint Protection.
  • Trend Micro
    • Policy View: zz[SYS] Policy - AV_Trend Micro
    • Description: Trend Micro - Applies monitoring for Trend Micro AntiVirus.

[System].Core.Org Specific Policies.Monitoring.Utility

  • Update Lists By Scan
    • Policy View: zz[SYS] Policy - OS_All Windows
    • Description:Update Lists By Scan - Applies a scheduled Update Lists By Scan to run on all Windows machines to keep performance counter, event log, and running services information current for each machine for accurate monitoring purposes.
  • Monitoring Cleanup
    • Policy View: zz[SYS] Policy - OS_All Windows
    • Description:Monitoring Cleanup - As the last policy that contains Alerts and Monitor Sets, this policy effectively ensures that previously applied monitoring, (Event Logs Alerts and Monitor Sets assigned via other policies that are no longer needed due to role changes, etc.) gets removed.

[System].Core.Org Specific Policies.Patch / Update Management.Windows.Common Windows Patch Mgmt Settings

  • Deny Patch Settings
    • Policy View: zz[SYS] Policy - Patch_Deny Patching Group
    • Description: Deny Patch Settings - Applies patch management settings to machines selected in the 'zz[SYS] Policy - Deny Patching Group' View. Sets Reboot Action to "If user logged in ask to reboot every 60 minutes until reboot occurs. Reboot if user not logged in". Sets Patch Policy Membership to the 'Deny Patching' patch policy. Sets Patch Alerts to generate an Alarm and Email the 'Patch Alerts' email address when a "Patch install fails" or the "Agent credential is invalid or missing".
  • Test Patch Settings
    • Policy View: zz[SYS] Policy - Patch_Test Patching Group
    • Description: Test Patch Settings - Applies patch management settings to machines selected in the 'zz[SYS] Policy - Test Patching Group' View. Sets Reboot Action to "If user logged in ask to reboot every 60 minutes until reboot occurs. Reboot if user not logged in". Sets Patch Policy Membership to the 'Test Patching' patch policy. Sets Patch Alerts to generate an Alarm and Email the 'Patch Alerts' email address when a "Patch install fails" or the "Agent credential is invalid or missing".
  • Disable Windows Automatic Update
    • Policy View: zz[SYS] Policy - Patch_Windows Auto Update Enabled
    • Description: Disable Windows Automatic Updates on machines that have Windows Automatic Update Enabled. If Windows Automatic Update is enabled and Kaseya patch management is being used, then Windows Automatic Update may conflict with the Kaseya patch management strategy and may result in the deployment of patches that have been denied or are still pending approval in Kaseya.
  • File Source Internet
    • Policy View: zz[SYS] Policy - OS_All Windows
    • Description: File Source Internet - Sets the File Source for patch management to the Internet for all Windows machines so that patches are downloaded directly from the Microsoft patch and download servers. This policy is the default and can be overridden with an alternate policy that is applied to specific orgs or machine groups and which has precedence over this policy.

[System].Core.Org Specific Policies.Patch / Update Management.Windows.Windows Workstation Patch Mgmt Settings

  • Workstation Patch Settings
    • Policy View:zz[SYS] Policy - OS_All Windows Workstations
    • Description: Workstation Patch Settings - Applies patch management settings to Windows Workstations. Sets Reboot Action to "If user logged in ask to reboot every 60 minutes until reboot occurs. Reboot if user not logged in". Sets Patch Policy Membership to the 'Workstation Patching' patch policy. Sets Patch Alerts to generate an Alarm and Email the 'Patch Alerts' email address when a "Patch install fails" or the "Agent credential is invalid or missing".
  • Daily Wkst Schedule for 10+ Patches (Auto Update M-F 6am-6pm/Power Mgmt)
    • Policy View: zz[SYS] Policy - Patch_Workstation Patching Policy Missing 10+ Patches
    • Description: Daily Wkst Schedule for 10+ Patches (Auto Update M-F 6am-6pm/Power Mgmt) - Applies Daily Auto Update schedules to Workstation Patching Policy members that are missing 10 or more approved patches. Auto Updates are scheduled M-F each week from 6am-6pm. This policy is generally used when customers have machines that are missing quite a few patches and they want to get those systems up to date over the course of days rather than weeks or months. Once the machines are patched, then they will not need to be patched on a daily basis anymore. Auto Updates are performed in the daytime to handle customers where machines are generally powered off at night, but the power management option is enabled on these schedules so that any machines powered off during the day can be woken up prior to performing these operations.
  • Weekly Wkst Schedule (Scan Tu 6am-6pm/Auto Update W 6am-6pm/Power Mgmt)
    • Policy View: zz[SYS] Policy - Patch_Workstation Patching Policy
    • Description: Weekly Wkst Schedule (Scan Tu 6am-6pm/Auto Update W 6am-6pm/Power Mgmt) - Applies Weekly Patch Scan and Auto Update schedules to Workstation Patching Policy members. Patch Scans are scheduled on Tue of each week from 6am-6pm and Auto Updates are scheduled on Wed of each week from 6am-6pm. This policy is generally used when customers want to take a more aggressive approach to patching to help minimize risk due to machines not being patched and thus want new patches deployed relatively quickly to machines. Auto Updates are performed in the daytime to handle customers where machines are generally powered off at night, but the power management option is enabled on these schedules so that any machines powered off during the day can be woken up prior to performing these operations.

[System].Core.Org Specific Policies.Patch / Update Management.Windows.Windows Server Patch Mgmt Settings

  • Server Patch Settings
    • Policy View:zz[SYS] Policy - OS_All Windows Servers
    • Description: Server Patch Settings - Applies patch management settings to Windows Servers. Sets Reboot Action to "Do not reboot after update", "When reboot required, send email to 'Patch Alerts' email address". Sets Patch Policy Membership to the 'Server Patching' patch policy. Sets Patch Alerts to generate an Alarm and Email the 'Patch Alerts' email address when a "Patch install fails" or the "Agent credential is invalid or missing".
  • Weekly Srvr Schedule (Scan W 6pm-6am)
    • Policy View:zz[SYS] Policy - OS_All Windows Servers
    • Description: Weekly Srvr Schedule (Scan W 6pm-6am) - Applies Patch Scan schedule to Server Patch Policy members. Patch Scans are scheduled on Wed of each week from 6pm-6am. No patch Auto Update deployments are scheduled on servers by this policy.

[System].Core.Org Specific Policies.Patch / Update Management.Windows.Other Windows Patch Mgmt Settings

  • File Source System Server
    • Policy View: zz[SYS] Policy - Network_10.11.12.x
    • Description: File Source System Server - Sets the File Source for patch management to the System Server for all Windows machines so that patches are downloaded centrally by the System Server and then distributed from the System Server to the machines being patched.

[System].Core.Org Specific Policies.Patch / Update Management.Windows.Other Windows Patch Mgmt Settings.Other Schedules.Daytime

  • Monthly Wkst Schedule (Scan 2nd W 6am-6pm/Auto Update 1st W 6am-6pm/Power Mgmt)
    • Policy View:zz[SYS] Policy - Patch_Workstation Patching Policy
    • Description: Monthly Wkst Schedule (Scan 2nd W 6am-6pm/Auto Update 1st W 6am-6pm/Power Mgmt) - Applies Patch Scan and Automatic Update schedules to Workstation Patch Policy members. Patch Scans are scheduled on the 2nd Wed of the month from 6am-6pm. Automatic Updates are scheduled on the 1st Wed of the Month from 6am-6pm. This policy is generally used when customers want to take a conservative approach to patch management since scans and updates are performed only once a month, and updates are deployed at the beginning of the month. This means that the patches being deployed have been released for at least a month which allows for extensive testing of patches prior to their general deployment. Scans and Automatic Updates are performed in the day to handle customers where machines are generally powered off at night, but the power management option is enabled on these schedules so that any machines powered off during the day can be woken up prior to performing these operations.

[System].Core.Org Specific Policies.Patch / Update Management.Windows.Windows Workstation Patch Mgmt Settings.Nighttime

  • Daily Wkst Schedule for 10+ Patches (Auto Update M-F 6pm-6am/Power Mgmt)
    • Policy View: zz[SYS] Policy - Patch_Workstation Patching Policy Missing 10+ Patches
    • Description: Daily Wkst Schedule for 10+ Patches (Auto Update M-F 6pm-6am/Power Mgmt) - Applies Daily Auto Update schedules to Workstation Patching Policy members that are missing 10 or more approved patches. Auto Updates are scheduled M-F each week from 6pm-6am. This policy is generally used when customers have machines that are missing quite a few patches and they want to get those systems up to date over the course of days rather than weeks or months. Once the machines are patched, then they will not need to be patched on a daily basis anymore. Automatic Updates are performed in the evening to help mitigate service disruption and the power management option is enabled on these schedules so that powered off machines can be woken up prior to performing these operations.
  • Weekly Wkst Schedule for 10+ Patches (Auto Update W 6pm-6am/Power Mgmt)
    • Policy View:zz[SYS] Policy - Patch_Workstation Patching Policy Missing 10+ Patches
    • Description:Weekly Wkst Schedule for 10+ Patches (Auto Update W 6pm-6am/Power Mgmt) - Applies Weekly Auto Update schedules to Workstation Patching Policy members that are missing 10 or more approved patches. Auto Updates are scheduled on Wed of each week from 6pm-6am. This policy is generally used when customers have machines that are missing quite a few patches and they want to get those systems up to date over the course of weeks rather than months. Once the machines are patched, then they will not need to be patched weekly anymore and will fall back to a monthly Patch Scan and Auto Update schedule. Auto Updates are performed in the evening to handle customers where machines are generally powered off at night, but the power management option is enabled on these schedules so that any machines powered off during the day can be woken up prior to performing these operations.
  • Weekly Wkst Schedule (Scan Tu 6pm-6am/Auto Update W 6pm-6am/Power Mgmt)
    • Policy View: zz[SYS] Policy - Patch_Workstation Patching Policy
    • Description: Weekly Wkst Schedule (Scan Tu 6pm-6am/Auto Update W 6pm-6am/Power Mgmt) - Applies Weekly Patch Scan and Auto Update schedules to Workstation Patching Policy members. Patch Scans are scheduled on Tue of each week from 6pm-6am and Auto Updates are scheduled on Wed of each week from 6pm-6am. This policy is generally used when customers want to take a more aggressive approach to patching to help minimize risk due to machines not being patched and thus want new patches deployed relatively quickly to machines. Scans and Automatic Updates are performed in the evening to help mitigate service disruption and the power management option is enabled on these schedules so that powered off machines can be woken up prior to performing these operations.
  • Monthly Wkst Schedule (Scan 2nd W 6pm-6am/Auto Update 1st W 6pm-6am/Power Mgmt)
    • Policy View: zz[SYS] Policy - Patch_Workstation Patching Policy
    • Description: Monthly Wkst Schedule (Scan 2nd W 6pm-6am/Auto Update 1st W 6pm-6am/Power Mgmt) - Applies Patch Scan and Automatic Update schedules to Workstation Patch Policy members. Patch Scans are scheduled on the 2nd Wed of the month from 6pm-6am. Automatic Updates are scheduled on the 1st Wed of the Month from 6pm-6am. Scans and Automatic Updates are performed in the evening to help mitigate service disruption and the power management option is enabled on these schedules so that powered off machines can be woken up prior to performing these operations. This policy is generally used when customers want to take a conservative approach to patch management since scans and updates are performed only once a month, and updates are deployed at the beginning of the month. This means that the patches being deployed have been released for at least a month which allows for extensive testing of patches prior to their general deployment.
  • Monthly Srvr Schedule (Scan 2nd W 6pm-6am)
    • Policy View: zz[SYS] Policy - Patch_Server Patching Policy
    • Description: Monthly Srvr Schedule (Scan 2nd W 6pm-6am) - Applies Patch Scan schedule to Server Patch Policy members. Patch Scans are scheduled on the 2nd Wed of the month from 6pm-6am. No patch Auto Update deployments are scheduled on servers by this policy.
  • Monthly Srvr Schedule (Scan 2nd W 6pm-6am/Auto Update 1st Su 12am-4am)
    • Policy View:zz[SYS] Policy - Patch_Server Patching Policy
    • Description: Monthly Srvr Schedule (Scan 2nd W 6pm-6am/Auto Update 1st Su 12am-4am) - Applies Patch Scan and Automatic Update schedules to Server Patch Policy members. Patch Scans are scheduled on the 2nd Wed of the month from 6am-6pm. Automatic Updates are scheduled on the 1st Sun of the Month from 12am-4am. This policy is generally used when customers want to take a conservative approach to patch management since scans and updates are performed only once a month, and updates are deployed at the beginning of the month. This means that the patches being deployed have been released for at least a month which allows for extensive testing of patches prior to their general deployment. Scans and Automatic Updates are performed on the weekend early in the morning so that production time and users are less affected by any service outages related to patching servers.

[System].Core.Org Specific Policies.Patch / Update Management.MacOS.MacOS Workstation Software Update Settings

  • Weekly MacOS Workstation Software Update (Install Recommended W 6am-6pm)
    • Policy View: zz[SYS] Policy - OS_All Mac OS X Workstations
    • Description: Weekly MacOS Workstation Software Update (Install Recommended W 6am-6pm) - Applies a Mac Software Update to run Wed 6am-6pm every week that will install recommended MacOS Software updates on MacOS Workstations. Software Updates are performed in the daytime to handle customers where machines are generally powered off at night, but the power management option is enabled on these schedules so that any machines powered off during the day can be woken up prior to performing these operations.

[System].Core.Org Specific Policies.Patch / Update Management.MacOS.MacOS Server Software Update Settings

  • Monthly MacOS Server Software Update (Install Recommended 1st Su 12am-4am)
    • Policy View: zz[SYS] Policy - OS_All Mac OS X Servers
    • Description: Monthly MacOS Server Software Update (Install Recommended 1st Su 12am-4am) - Applies a Mac Software Update to run on the 1st Sun of every month that will install recommended MacOS Software updates on MacOS Servers. This will keep the Mac Servers current with recommended updates.

[System].Core.Org Specific Policies.Patch / Update Management.MacOS.Other MacOS Software Update Settings

  • Monthly MacOS Workstation Software Update (Install Recommended 1st W 6am-6pm)
    • Policy View: zz[SYS] Policy - OS_All Mac OS X Workstations
    • Description: Monthly MacOS Workstation Software Update (Install Recommended 1st W 6am-6pm) - Applies a Mac Software Update to run on the 1st Wed of every month from 6am-6pm that will install recommended MacOS Software updates on MacOS Workstations. Software Updates are performed in the daytime to handle customers where machines are generally powered off at night, but the power management option is enabled on these schedules so that any machines powered off during the day can be woken up prior to performing these operations.
  • Monthly MacOS Workstation Software Update (Install Recommended 1st W 6pm-6am)
    • Policy View: zz[SYS] Policy - OS_All Mac OS X Workstations
    • Description: Monthly MacOS Workstation Software Update (Install Recommended 1st W 6pm-6am) - Applies a Mac Software Update to run on the 1st Wed of every month from 6pm-6am that will install recommended MacOS Software updates on MacOS Workstations. Software Updates are performed in the evening to help mitigate service disruption and the power management option is enabled on these schedules so that powered off machines can be woken up prior to performing these operations.
  • Monthly MacOS Workstation Software Update (Install All 1st W 6pm-6am)
    • Policy View: zz[SYS] Policy - OS_All Mac OS X Workstations
    • Description: Monthly MacOS Workstation Software Update (Install All 1st W 6pm-6am) - Applies a Mac Software Update to run on the 1st Wed of every month from 6pm-6am that will install all MacOS Software updates on MacOS Workstations. Software Updates are performed in the evening to help mitigate service disruption and the power management option is enabled on these schedules so that powered off machines can be woken up prior to performing these operations.

[System].Core.Org Specific Policies.Patch / Update Management.Linux

  • Monthly Linux Package Updates/Upgrades (Install 1st W 6pm-6am)
    • Policy View:zz[SYS] Policy - OS_All Linux
    • Description:Monthly Linux Package Updates/Upgrades (Install 1st W 6pm-6am) - Applies a Linux Package Update/Upgrades procedure to run on the 1st Wed of every month. This will keep Linux machines updated and current for the various software components that are installed.